Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72. | |
| Title | Claude Code has a Command Injection in find Command Bypasses User Approval Prompt | |
| Weaknesses | CWE-78 CWE-94 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T21:19:42.986Z
Reserved: 2026-01-27T19:35:20.528Z
Link: CVE-2026-24887
Updated: 2026-02-03T21:19:37.560Z
Status : Received
Published: 2026-02-03T21:16:13.433
Modified: 2026-02-03T21:16:13.433
Link: CVE-2026-24887
No data.
OpenCVE Enrichment
No data.